Memory Corruption in Unbound by NLnet Labs
CVE-2026-52863

5.9MEDIUM

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-52863?

The vulnerability in Unbound versions 1.25.0 to 1.25.1 stems from an issue in the interaction between the 'respip' and 'dns64' modules, which can produce a shallow copy of the view name. This may lead to potential memory corruption if the original view owner is removed during high load conditions. The issue arises when Unbound is performing under pressure while configured with specific modules alongside 'access-control-view'. In scenarios where the jostle logic becomes active and starts discarding slow queries, incorrect handling may result in memory corruption. Although the likelihood of a crash is low due to dependence on the memory allocator, configurations utilizing debug memory builds (such as ASAN) may lead to server termination upon memory corruption detection.

Affected Version(s)

Unbound 1.25.0 < 1.25.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang (Palo Alto Networks)
.